VYPR
Medium severity5.3NVD Advisory· Published May 9, 2022· Updated Jun 17, 2026

CVE-2019-25060

CVE-2019-25060

Description

The WPGraphQL WordPress plugin before 0.3.5 doesn't properly restrict access to information about other users' roles on the affected site. Because of this, a remote attacker could forge a GraphQL query to retrieve the account roles of every user on the site.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
wp-graphql/wp-graphqlPackagist
< 0.3.50.3.5

Affected products

3

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.